Practical governance · EU AI Act · Updated 7 August 2026

AI Governance & EU AI Act

A practical implementation guide for organizations operating in Germany and the EU. Turn the EU AI Act, GDPR and ISO/IEC 42001 into an operating model with clear ownership, AI inventories, risk decisions, lifecycle gates, evidence, monitoring and staff literacy.

What applies now

The AI Act is already an operational compliance topic. Several obligations now apply and are enforceable, while the 2026 Digital Omnibus gives organizations more time for key high-risk requirements. Use that time to build repeatable governance rather than postpone implementation.

Applied since 2 Feb 2025Prohibited AI practices

Screen pilots, procurement and production systems for prohibited practices and create a clear stop-and-escalate path.

Enforced from 2 Aug 2026AI literacy

Providers and deployers must take measures supporting AI literacy for relevant staff. Keep role-based training evidence.

Applies from 2 Aug 2026Article 50 transparency

Disclosure and content-transparency duties now apply, including specified AI interactions and generated/manipulated content.

Prepare for 2027 / 2028High-risk obligations

Key requirements for Annex III and product-safety-linked high-risk systems now phase in later under the amended timetable.

2026 legal update: Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended the rollout. Older guides that say the main high-risk obligations all began in August 2026 are no longer current.

Interactive governance tools

Use these lightweight tools to explore likely governance needs and track whether the basics are in place. They are orientation aids, not legal determinations.

Risk helper

Quick AI use-case assessment

Answer four questions to get a practical governance signal and suggested next steps.

Readiness tracker

Governance essentials

Mark what your organization already has. Your progress is saved in this browser.

0%
Guide search

Find a topic quickly

AI governance operating model

Good AI governance connects executive accountability to everyday product, procurement, IT, privacy and risk workflows. The objective is consistent, proportionate and traceable decisions—not a separate bureaucracy for every low-risk tool.

1 · Principles

Policy and risk appetite

Define allowed, restricted and prohibited uses; privacy and confidentiality rules; human oversight; transparency expectations; vendor requirements; incident escalation; and exception handling.

2 · Ownership

Decision rights

Assign an executive sponsor, AI governance lead, system owners, legal/privacy/security reviewers and a forum for material or ambiguous cases.

3 · Lifecycle

Govern from intake to retirement

Integrate registration, classification, impact assessment, testing, approval, monitoring, change management and retirement into existing workflows.

4 · Assurance

Evidence, monitoring and challenge

Maintain an AI inventory, assessment records, approvals, test results, training evidence, logs, incident records and periodic control testing.

Suggested governance responsibilities

Role / forumPrimary purposeTypical decisions
Executive sponsorSet accountability, risk appetite and resources.Approve AI policy, major residual risk and remediation funding.
AI governance committeeResolve cross-functional, high-impact or unclear cases.Approve sensitive pilots, high-risk systems, exceptions and control standards.
AI governance lead / officeRun the governance process and maintain standards.Inventory quality, classification workflow, evidence standards and reporting.
System / use-case ownerOwn purpose, controls, monitoring and changes.Define oversight, accept operating conditions and escalate incidents.
Independent assuranceTest whether governance and controls actually work.Audit, control testing, findings and remediation verification.

Minimum AI inventory fields

Identity

System name, vendor/model, version, business owner, technical owner, status and deployment environment.

Purpose & impact

Intended purpose, users, affected people, decision significance, sector, geography and business process.

Legal classification

Provider/deployer/importer/distributor role, prohibited/high-risk assessment, Article 50 triggers and GPAI dependencies.

Data & controls

Personal/confidential data, retention, transfers, human oversight, access, testing, logging, security and monitoring.

Goals of the EU AI Act

The EU AI Act aims to create a common legal environment for AI across EU Member States while supporting safe and trustworthy AI development.

Trustworthy AI

Safety and fundamental rights

AI systems should be safe for users and respect privacy, equality, non-discrimination, human dignity, and other fundamental rights.

Foster innovation

Responsible adoption

The framework encourages responsible AI development across sectors while reducing legal fragmentation.

Harmonize rules

One EU framework

A unified regulatory environment helps organizations understand expectations across all EU Member States.

Safe

Systems should be assessed and managed so they do not create unacceptable risks for users.

Transparent

Users should understand when AI is being used and how it operates where transparency duties apply.

Traceable

Development and operation should be documented, logged, and auditable where required.

Non-discriminatory

AI systems should avoid biased or discriminatory outcomes and use appropriate data governance.

Environmentally responsible

Organizations should consider environmental impact in AI development and use.

EU AI Act risk hierarchy

The higher the risk to people’s rights, safety, or livelihoods, the stronger the legal obligations.

Unacceptable

Examples: social scoring, manipulative uses, and certain biometric surveillance practices.

Requirement: banned.

High

Examples: hiring, education, critical infrastructure, law enforcement, migration, public benefits, and essential services.

Requirement: strict compliance, documentation, risk management, human oversight, and monitoring.

Limited

Examples: chatbots, deepfakes, and certain user-facing AI interactions.

Requirement: transparency obligations.

Minimal

Examples: spam filters, AI in games, and low-impact internal tools.

Requirement: no specific AI Act obligations, though other laws may still apply.

GDPR and AI

The AI Act does not replace GDPR. Whenever AI processes personal data, organizations generally need to comply with both frameworks.

Privacy by design

Build protection in from day one

Data protection should be embedded into AI systems from the outset, not retrofitted later.

Security by default

Collect only what is necessary

Use the minimum personal data needed and protect it with appropriate technical and organizational measures.

Accountability

Document everything

Organizations must be able to demonstrate compliance through records, policies, assessments, and evidence of controls.

Lawful basis

AI systems need a valid legal basis before processing personal data, such as consent, contract, legal obligation, public task, vital interests, or legitimate interests.

Data minimization

Only data strictly necessary for the task should be collected, retained, or used for model inputs and outputs.

Human oversight

Humans should be able to review automated decisions that significantly affect individuals.

Define who may override, stop or escalate the system and what information they need to do so.

Key rights for individuals

Information about automated decision-making

Where GDPR rules on automated decision-making apply, individuals may be entitled to information about the logic involved, significance and envisaged consequences, together with relevant safeguards.

Right to be forgotten

Individuals can request deletion of personal data when legal conditions are met.

Data portability

Individuals may be able to move their data from one service provider to another in a structured, commonly used format.

Right to notification

People may need to be informed if a personal data breach creates relevant risks to their rights and freedoms.

Compliance terminology and responsibilities

AI governance requires clear ownership. Organizations should know whether they are developing, placing, importing, distributing, or deploying an AI system.

Provider

Entity that develops or places an AI system on the market under its own name or trademark.

Deployer

Person or organization using an AI system under its authority in business or public-sector operations.

GPAI

General-purpose AI models that can support a wide range of downstream tasks.

DPIA

Data Protection Impact Assessment, used to evaluate risks from personal data processing.

DPO

Data Protection Officer responsible for advising on and monitoring data protection compliance.

BDSG

Bundesdatenschutzgesetz, Germany’s Federal Data Protection Act.

Identify and classify AI systems

Inventory AI tools and map each one to the EU AI Act risk tier. Include internal, third-party, and embedded AI tools.

Conduct DPIAs where required

Run DPIAs when AI processing is likely to create high risks for individuals, especially with sensitive or large-scale data.

Implement TOMs

Establish technical and organizational measures such as access controls, encryption, logging, vulnerability management, and data leakage safeguards.

Mandate AI literacy

Train staff who use, procure, or manage AI tools so they understand risks, limitations, appropriate use, and escalation routes.

Assign governance owners

Define responsibilities across legal, privacy, security, procurement, HR, IT, business teams, and the DPO where applicable.

Govern the full AI lifecycle

Attach governance to business gates that already exist. A material change to purpose, model, vendor, data, users, geography or automation level should be able to trigger re-assessment.

01 · Discover

Register

Capture owner, tool/model, purpose, data and affected people.

Suggested output: inventory record, owner, purpose statement, vendor/model and affected population.
02 · Assess

Classify

AI Act role/risk, privacy, security, rights and sector risks.

Suggested output: classification rationale, DPIA/FRIA decision, security and vendor review needs.
03 · Design

Control

Define oversight, testing, logging, data and transparency controls.

Suggested output: control plan, test criteria, human oversight design and disclosure requirements.
04 · Approve

Gate

Record reviewers, conditions, residual risk and decision.

Suggested output: approval record, conditions, exceptions, owners and residual-risk acceptance.
05 · Operate

Monitor

Track incidents, complaints, quality, misuse and changes.

Suggested output: monitoring metrics, incident log, complaints, model/vendor changes and review cadence.
06 · Retire

Close

Remove access, handle retained data and archive evidence.

Suggested output: closure record, access removal, data disposition and archived evidence.

AI control & evidence library

A standard control library makes assessments faster and more consistent. Scale the depth by risk, role, data sensitivity and decision impact.

Purpose & scope

Approved purpose, excluded uses, target users/population, benefit, risk owner and re-assessment triggers.

Check purpose changes, excluded uses and accountable owner at each major change.

Data governance

Quality, provenance, representativeness, minimization, sensitive data, retention, deletion and training/fine-tuning rules.

Evidence can include source/provenance notes, retention rules, minimization decisions and dataset checks.

Human oversight

Reviewer authority, competence, intervention point, override capability, escalation route and workload.

Testing & validation

Accuracy, robustness, bias/fairness, harmful outputs, edge cases, prompt injection, security and acceptance criteria.

Set pre-release acceptance criteria and repeat tests after material model, data or workflow changes.

Transparency

User disclosures, instructions, limitations, AI-generated content marking and decision information where applicable.

Check user notices, chatbot disclosure, synthetic-content marking and decision information obligations.

Security

Access, secrets, endpoints, supply chain, data leakage, adversarial testing, vulnerabilities and secure configuration.

Include prompt injection, data leakage, access controls, secrets, integrations and supply-chain risks.

Vendor management

Documentation, data use, subprocessors, transfers, retention, security, incident notice, audit rights and model-change notices.

Track contracts, subprocessors, data use, retention, security commitments and model-change notification.

Monitoring

Quality, drift, override rate, complaints, incidents, harmful outputs, misuse, vendor/model changes and review cadence.

Define measurable signals such as incident count, quality, harmful outputs, override rate and complaints.

Evidence pack

Governance evidence

AI policy, committee charter, RACI, risk appetite, approval matrix and exception process.

System evidence

Inventory entry, classification rationale, technical/system documentation, test results and version history.

Assessment evidence

AI risk/impact assessment, DPIA, FRIA where applicable, security review and vendor due diligence.

Operational evidence

Monitoring reports, incidents, complaints, corrective actions, training records and re-assessments.

90-day governance roadmap

Days 1–30 · Discover and stop obvious risk

Create the AI inventory, publish interim acceptable-use rules, identify prohibited/sensitive use cases, nominate owners and map major vendors/models.

Days 31–60 · Standardize assessments

Launch a common intake form, classification method, privacy/security/vendor review, role-based AI literacy and approval matrix.

Days 61–90 · Operationalize evidence

Set monitoring and change triggers, establish governance reporting, test incident escalation, document exceptions and prioritize high-risk readiness.

Target state: every material AI use has a named owner, a current classification, proportionate controls, a traceable approval decision and a defined monitoring/review path.

ISO 42001 & AI Governance

ISO/IEC 42001 is the world's first international standard for Artificial Intelligence Management Systems (AIMS). It provides a structured framework to govern AI risks, demonstrate accountability, and bridge the gap to regulatory requirements like the EU AI Act.

AIMS

Management System

Establishes policies, roles, and processes to ensure AI is developed and used responsibly across the organization.

PDCA Approach

Continuous cycle

Operates on a Plan-Do-Check-Act lifecycle to continuously monitor AI performance, adapt to threats, and improve controls.

Impact Assessment

Evaluating risks

Requires organizations to conduct impact and risk assessments for AI systems to address bias, transparency, and fairness.

Lifecycle governance

Embeds oversight into every stage—from inception and design to deployment, monitoring, and eventual retirement.

Regulatory alignment

Serves as objective evidence of due diligence, helping organizations demonstrate readiness for the EU AI Act and GDPR.

Third-party oversight

Defines controls for managing compliance risks when using external AI solutions, cloud AI platforms, or third-party vendors.

Violations, fines, and enforcement

Maximum fines depend on the law, violation type, and organization size. Treat these as headline maximums and confirm with legal counsel.

GDPR serious breachesUp to €20 million or 4%

Major infringements, such as serious violations of basic processing principles or data subject rights.

GDPR less severe breachesUp to €10 million or 2%

Certain governance, recordkeeping, and security-related obligations.

EU AI Act prohibited AI useUp to €35 million or 7%

Prohibited AI practices under the EU AI Act.

EU AI Act other violationsUp to €15 million or 3%

Many other AI Act obligations depending on the infringement.

Important EU AI Act milestones

1 August 2024

Entry into force

The EU AI Act entered into force, starting the phased implementation timeline.

February 2025

Prohibited practices and AI literacy

Rules on banned practices and AI literacy obligations began applying.

August 2025

GPAI obligations begin

Obligations for general-purpose AI models start applying, with transition rules for some existing models.

2 August 2026

Transparency and enforcement phase

Article 50 transparency duties apply. AI literacy supervision/enforcement and Commission enforcement powers for GPAI providers are active.

2 December 2027

Annex III high-risk phase

Key high-risk requirements for systems classified under Article 6(2) / Annex III apply under the amended Digital Omnibus timetable.

2 August 2028

Product-safety-linked high-risk phase

Key requirements for high-risk systems linked to regulated products under Article 6(1) / Annex I apply under the amended timetable.

Article 50 grace period: for certain generative AI systems placed on the market before 2 August 2026, the Article 50(2) marking/detection obligation applies from 2 December 2026.

Common governance questions

Do we need a committee review for every AI tool?

No. Use proportionality. Low-risk tools can follow a streamlined path, while high-impact, novel, ambiguous or sensitive use cases should receive deeper cross-functional review.

Can we rely only on a vendor's AI Act classification?

No. Vendor information is useful, but your own role and context of use can create deployer obligations, privacy risks or sector-specific requirements the vendor cannot fully assess for you.

Does ISO/IEC 42001 certification equal EU AI Act compliance?

No. It provides a management-system structure for responsible AI governance and continual improvement, but specific legal obligations still need to be mapped to your systems, roles and use cases.

Do internal and experimental AI tools belong in the inventory?

Yes. Internal tools can still process employee, customer, confidential or sensitive data and may create security, discrimination, decision or prohibited-use risks.

What should trigger re-assessment?

Consider a re-review when intended purpose, model/version, vendor, data, population, geography, automation level, integrations, performance, incidents or applicable law materially change.

Primary sources

Use this guide for operational orientation, then verify material decisions against the current consolidated legal text and official guidance.

Not legal advice. Applicability depends on the specific AI system, organizational role, sector, jurisdiction, facts and current law. Maintain regulatory-change monitoring and obtain qualified legal advice for material decisions.

Additional facts organizations should not miss

AI Act compliance is not only an IT issue

Legal, privacy, security, procurement, HR, operations, and business owners all need defined responsibilities.

Vendor AI tools still need review

Using a third-party AI system does not remove the need to assess contracts, data flows, risk tier, security, and user obligations.

Training data quality matters

Poor, biased, incomplete, or unrepresentative data can create discrimination, inaccuracy, and compliance problems.

Logs and documentation are evidence

Risk assessments, model cards, DPIAs, incident records, access logs, vendor due diligence, and monitoring reports help demonstrate accountability.

Human oversight must be meaningful

Reviewers need authority, training, time, and information to challenge AI outputs rather than rubber-stamp them.

Prompts and outputs can contain sensitive data

Prompts may contain personal data or confidential information. Outputs may become records that need retention, review, or deletion controls.